PT-2021-17067 · Directus · Directus

Arnaud Courty

+1

·

Published

2021-02-23

·

Updated

2024-08-03

·

CVE-2021-26594

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Directus versions 8.x through 8.8.1
Description An issue exists where an attacker can switch to the administrator role without any control by the back end, using the PATCH method. This issue only affects products that are no longer supported by the maintainer.
Recommendations For versions 8.x through 8.8.1, as a temporary workaround, consider restricting access to the PATCH method until a solution is available. However, since these versions are no longer supported, the primary recommendation is to upgrade to a supported version if possible. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2021-26594

Affected Products

Directus